CVE-2016-7051
HIGHjackson-dataformat-xml < 2.7.8 - Server-Side Request Forgery via DTD Processing
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2016-7051. PoCs published by dawetmaster, andikahilmy.
AI-analyzed exploit summary This repository appears to be a fork or mirror of the legitimate Jackson XML dataformat library, but it does not contain any exploit code or proof-of-concept for CVE-2016-7051. The files listed are standard library files without any modifications or exploit-specific content.
Description
XmlMapper in the Jackson XML dataformat component (aka jackson-dataformat-xml) before 2.7.8 and 2.8.x before 2.8.4 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors related to a DTD.
Exploits (2)
This repository appears to be a fork or mirror of the legitimate Jackson XML dataformat library, but it does not contain any exploit code or proof-of-concept for CVE-2016-7051. The files listed are standard library files without any modifications or exploit-specific content.
This repository contains a vulnerable version of the Jackson dataformat XML library, specifically targeting CVE-2016-7051. The code includes the necessary Java classes to demonstrate the vulnerability, which involves deserialization issues in XML processing.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N